Your journey
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
0 of 34 units

You are in Degree 5 · Governance and resilienceunit 2 of 6Ahead of you: An approved use policy and a completed maturity assessment.

Degree 5 · Unit 5.2

ISO 42001 in practice

The international standard ISO/IEC 42001 is the first standard written for an AI management system. Do not be put off by the word "standard": its structure is the structure of every management system you have ever known — a policy, roles, a risk assessment, controls, monitoring, and periodic improvement. What is new here is not the structure at all, but what you are assessing: a system that learns, whose behaviour changes over time, and that affects real people.

FIG. 26 — The system cycle
1
Plan
Scope, policy, roles, the system register, risk and impact assessment
2
Do
Controls, training, supplier management, control of the system lifecycle
3
Check
Performance indicators, incident log, internal audit, management review
4
Improve
A corrective action, dated and owned — otherwise the cycle is decoration
↻

The six indispensable documents

1
The system register
Every use of AI in your organisation, its owner, its data, and its risk level. Start here — most organisations are surprised by the length of the list.
2
The policy
Two pages. Permitted, forbidden, requires approval.
3
The roles matrix
Who approves, who operates, who reviews, who stops it. By name, not by job title.
4
The impact assessment
For every high-risk system — who is affected, how, and what their safeguard is.
5
Supplier controls
What does your provider do with your data? Do they train on it? Where is it stored? What is the notice of change?
6
The incident log
What happened, when it was discovered, and what changed afterwards. Without this log there is no organisational learning.
Six clauses that build an information security management system

The framework is not a list of tools but a complete management cycle, from scope to improvement — the same structure ISO 42001 rests on.

FIG. B24 — The standard's six clauses
1Riskassessment2Securitycontrols3Policies andprocedures4Monitoringand review5Performancemeasurement6ImprovementimprovementISO27001
Scope and leadership come before the circle: without a documented scope and a leadership commitment, the loop turns in mid-air.

Scope and leadership come before the circle: without a documented scope and a leadership commitment, the loop turns in mid-air. And the second clause is the key to the rest: a system without leadership commitment stays as documents in a drawer, not a living management system.

The shape of the two-page policy

Permitted without permission
Internal drafts, summarising public material, generating ideas, explaining concepts, programming help on non-confidential code.
Requires approval
Any client data, any output going out in the organisation's name, any system that carries out actions, any new tool.
Absolutely forbidden
Sensitive personal data in a public system, a final decision touching a person, publishing content without human review, citing a reference that was not opened.
Fixed in every case
Whoever signs, guarantees. Review is documented. Incidents are reported within 24 hours, blame-free.
Organisational, people, physical, technological

Annex A sorts the controls into four themes — and letting one slip brings the others down.

FIG. B25 — The themes, as they land in a creative studio
Access control
Authenticating and authorising the user
Asset management
Inventory and classification of data
Encryption
Protecting data in transit and at rest
Physical security
Protecting premises and equipment
Operations security
Monitoring and sound procedure
Communications security
Safe exchange of information
Systems development
Secure coding and testing
Supplier relations
Managing third-party risk
Incident management
Detection, response and recovery
Business continuity
Disaster recovery and resilience
Compliance
Regulatory obligation and audit
Human resources
Training and awareness programmes
OrganisationalPeoplePhysicalTechnological

The people theme is usually the weakest and the cheapest to fix: most breaches begin with a click, not with a flaw in code.

Do this

  1. 1 — In your field. Build the system register: ask three colleagues which tools they actually use. Compare that with what you assumed.

  2. 2 — In writing. Write the two-page policy for your organisation in the shape above. This is half the gate of this degree.

  3. 3 — A test. Give the policy to a colleague who had no part in writing it, and ten minutes later ask them three applied questions. If they hesitate, redraft — do not blame.

Where to after this unit? You have governed the intelligence. The next unit protects what cannot be touched: the idea, the design and the identity.